CVE-2026-59939 @ Matrix
Status
new
Priority
1.75
Match score
4.0
Risk
DoS
Remote
CVSS
7.5 HIGH
Reason
cpe: httplib2; pkgs: httplib2; version: in-range: python3-httplib2-0.20.4-3, httplib2-0.20.4-3; debian:bookworm python-httplib2 open; risk:dos
Created
2026-08-21T10:16:27Z
Updated
2026-08-22T10:15:32Z
Package interrogation (copy)
Run on the host — click to copy a command. Debian/apt
| Package | Commands |
|---|---|
| python3-httplib2-0.20.4-3 | |
| httplib2-0.20.4-3 |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: python3-httplib2 · httplib2
| System | Matches | Ticket for CVE-2026-59939 | |
|---|---|---|---|
| Bullseye | python3-httplib2 0.18.1-3 | new open | |
| Matrix | python3-httplib2 0.20.4-3 | new open | |
| Silk | python3-httplib2 0.20.4-3+deb12u1 | new open |
Related CVE (same fix)
Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.
Host OS / kernel
OS
Debian GNU/Linux 12 (bookworm)
(12)
· debian
Arch
x86_64
kernel_release
uname -r → 6.1.0-52-amd64kernel_version
uname -v → #1 SMP PREEMPT_DYNAMIC Debian 6.1.180-1 (2026-08-03)For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Same CVE on other hosts
Open the ticket for this CVE on another system.
| System | Status | Priority | Updated | |
|---|---|---|---|---|
| Silk | new | 4.0 | 2026-08-22T10:15:32Z | Open |
| Bullseye | new | 0.62 | 2026-08-22T10:15:32Z | Open |
Description
httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0.
Update status
Add note only
References
- https://github.com/httplib2/httplib2/commit/87581ad6cf752fe3da2090c59058261d2d00a427
- https://github.com/httplib2/httplib2/releases/tag/v0.32.0
- https://github.com/httplib2/httplib2/security/advisories/GHSA-j5g9-f88f-gfj3
- https://lists.debian.org/debian-lts-announce/2026/08/msg00039.html
- https://github.com/httplib2/httplib2/security/advisories/GHSA-j5g9-f88f-gfj3
NVD: CVE-2026-59939